CVE-2022-50845 describes an inode leak vulnerability in the Linux kernel's ext4 filesystem, specifically within the ext4_xattr_inode_create() function. This flaw can occur when setting extended attributes, leading to unattached zero-length inodes if ext4_mark_inode_dirty() fails. The vulnerability has a low FAUCET Risk Score of 7/100, indicating a limited potential impact, primarily filesystem corruption requiring manual intervention. There is no public information regarding active exploitation, exploit code availability, or significant community discussion, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 4.13CNA affecteddefault affected | |
| Linux | Linux | >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 0f709e08caffb41bbc9b38b9a4c1bd0769794007, >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 322cf639b0b7f137543072c55545adab782b3a25, >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 70e5b46beba64706430a87a6d516054225e8ac8a, >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 9882601ee689975c1c0076ee65bf222a2a35e535, >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 9ef603086c5b796fde1c7f22a17d0fc826ba54cb, >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < e4db04f7d3dbbe16680e0ded27ea2a65b10f766a, >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < eab94a46560f68d4bcd15222701ced479f84f427, >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < fdaaf45786dc8c17a72901021772520fceb18f8cCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.